Interesting to see real world figures for bcrypt, also interesting that 7Zip's hashing algorithm seems extremely resilient (I assume it works on the same kind of difficulty / work factor that bcrypt uses but with a higher factor)
Slightly tangential but: 7zip amazes me. It hasn't been regularly updated for years, and still comes out on top of most benchmarks. And yet I find that many, if not most, people on Windows use WinRAR. It's good software, easy to install, easy to use, and it doesn't nag the user with warnings about licensing. I don't quite understand how WinRAR got popular in the first place with that kind of competition.
Password Cracking with 8x Nvidia GTX 1080 Ti GPUs
71–80 of 113 posts
Re: Password Cracking with 8x Nvidia GTX 1080 Ti GPUs
#72We all know MD5 is broken, but looking at it from purely a brute-force perspective: If you look at a US English keyboard, you've generally got 47 unique character keys. Let's double it and say there are 100 different characters you can type just using the character keys and shift. This machine could brute-force crack any 6 character password in under 4 seconds, any 7 character password in just over 6 minutes, and any…
As a non-infosec guy, could someone shed more light on the implications for end users? I get that the combination of password reuse, short passwords and the fact that some services store passwords in plain text or as MD5 hashes makes it easy to break into accounts once a single service is compromised. So my takeaway is not to use longer passwords, but to use a password manager and have unique passwords for every serv…
Re: Password Cracking with 8x Nvidia GTX 1080 Ti GPUs
#73Earlier quoted context omitted.
Am i correct in assuming that floating point operations would stress these machines even more so, so in other words if the hash computation somehow required lots of floating point calculations the time taken to crack would be much longer?
There aren't any widely used hashes that require floating point computations. Other than that, floating point instructions are usually slower.
Re: Password Cracking with 8x Nvidia GTX 1080 Ti GPUs
#74In 2010 I built an 8-GPU machine[1] (4 dual-GPU AMD HD5970) and wrote an MD5 bruteforcer (then faster than hashcat), doing 28.6 then 33.1 billion passwd hashes/sec with a software optimization: http://blog.zorinaq.com/whitepixel-breaks-286-billion-passwo... It's interesting to note that 6.5 years later a single GPU like the Nvidia 1080 Ti can match the whole 2010 machine (32 billion hashes/sec). This is a doubling of…
> incidentally posting this machine on HN is how I got pointed to Bitcoin thanks to the reply of a HN user :) Mining in 2010 with such a machine. That must have yielded a considerable ROI.
Re: Password Cracking with 8x Nvidia GTX 1080 Ti GPUs
#75Re: Password Cracking with 8x Nvidia GTX 1080 Ti GPUs
#76We all know MD5 is broken, but looking at it from purely a brute-force perspective: If you look at a US English keyboard, you've generally got 47 unique character keys. Let's double it and say there are 100 different characters you can type just using the character keys and shift. This machine could brute-force crack any 6 character password in under 4 seconds, any 7 character password in just over 6 minutes, and any…
As a non-infosec guy, could someone shed more light on the implications for end users? I get that the combination of password reuse, short passwords and the fact that some services store passwords in plain text or as MD5 hashes makes it easy to break into accounts once a single service is compromised. So my takeaway is not to use longer passwords, but to use a password manager and have unique passwords for every serv…
1) Don't use a really bad password like 'password'.
This one is the most important because it might allow an attacker to compromise your accounts online--that is without compromising the site itself.
2) Use a different password for each site.
This one is important because you don't want a compromise of smallvillelittleleague.org, which stores its passwords in plaintext, to mean that an attacker now has access to your banking accounts.
3) Use 2-factor on high importance / risk websites.
4) Use very strong passwords everywhere (i.e. long randomly generated).
If you've done 1-3 above the scenario where having a very strong password over a medium strength password is of concrete benefit is fairly narrow. It requires that the attacker get a website's password hashes, that the hash used be a fairly weak one, but that the website not be totally owned (because if it was then there's no additional benefit to having your site specific password).
All IMO of course.
Re: Password Cracking with 8x Nvidia GTX 1080 Ti GPUs
#77Earlier quoted context omitted.
> incidentally posting this machine on HN is how I got pointed to Bitcoin thanks to the reply of a HN user :) Mining in 2010 with such a machine. That must have yielded a considerable ROI.
Someone in that thread calculated 50 coins per 26minutes. Assuming they didn't sell any, that would be worth $250k/hour today...
Re: Password Cracking with 8x Nvidia GTX 1080 Ti GPUs
#78Earlier quoted context omitted.
The regret I feel having given away all of my 100 bitcoins at that price point will forever haunt me.
You can get over that feeling very quickly by reminding yourself to focus on what you might be missing out on today that you don't want to regret in years from now.
Bitcin turned anyone who bought even just a few dollars of it in 2009-2010 and held, rich And those who bought $1000s if it in 2011 into millionaires. This may be is the greatest gain of any tradeable instrument in the history of civilization. You can't find those kind of returns anywhere else, short of investing in the next Uber or Facebook but those were private ventures and unlike Bitcoin not open to the public.
Selling 1000 books on amazon for $8, although virtually possible for ordinary people to d, is like a piddly 3 bitcoins that any fool could have bought have bought in 2012. Goes to show how capital beats labor. To get rich, look for things that will go up and put your money in it early. Easier said than done, but the returns are astronomical when you get it right.
Re: Password Cracking with 8x Nvidia GTX 1080 Ti GPUs
#79Earlier quoted context omitted.
Seconded. The bitcoin to USD ratio is like 1 to 2700 right now http://www.xe.com/currencycharts/?from=XBT&to=USD
What's caused the price to rise so much the past few months?
Bitcoin is a form of safety and asset diversification in a world of economic uncertainty. Wealthy foreigners like bitcoin because it is in many instances safer than keeping money in a bank
Re: Password Cracking with 8x Nvidia GTX 1080 Ti GPUs
#80In 2010 I built an 8-GPU machine[1] (4 dual-GPU AMD HD5970) and wrote an MD5 bruteforcer (then faster than hashcat), doing 28.6 then 33.1 billion passwd hashes/sec with a software optimization: http://blog.zorinaq.com/whitepixel-breaks-286-billion-passwo... It's interesting to note that 6.5 years later a single GPU like the Nvidia 1080 Ti can match the whole 2010 machine (32 billion hashes/sec). This is a doubling of…
> Moore's Law is still alive and kicking (contrary to what many claim)! That statement is so often misunderstood, in multiple ways. First off, Moore's Law isn't technically about performance increases. It's about doubling of transistors every 2 years on the same die space. We still got that on CPUs until very recently, even though CPU performance has stopped doubling every 2 years like 15 years ago. But now even the…
Moore's law is fuzzy and has been for a while. I doubt if even Moore has the authority to say what it is about anymore.
When one person hears "Moore's law" or any other words what are the chances the person hearing those words is thinking the same thing as the speaker? For some words the listener hears the same thing the speaker intended, but I don't think it is for these words anymore.
Performance is still exponential the practical of Moore's law is still real.